In FedRAMP [4], the CP specifies the security
categorization of services delivered on their cloud platform.
However, this is not sufficient as the CP does not have
sufficient knowledge about the impact of information
security breaches on their tenants’ business objectives. Our
approach enables CCs to be involved in specifying the
security categorization of their information. Moreover, our
approach enables both scenarios where we can consider the
security categorization (SC) per tenant or per service.
The security categorization of the service is calculated as the
maximum of all tenants’ categorizations: